Jump to content

Windows fix disk virus


Recommended Posts

Hello Forum,

I hope I've followed all the directions regarding posting here. Yesterday I hit a virus called Windows Fix Disk. It appears to have made changes to my registry, as I cannot access any files or folders. I was able to run MBAM, which found 7 entries that were removed, but I am still having trouble. I would be grateful for any and all help you may provide me with.

Thanking you in advance!

I'm attaching the ARK log and the Rootkit log and am pasting in the DDS and the MBAM info. My apologies if I have done anything incorrectly.

DJ

.

DDS (Ver_11-03-05.01) - NTFSx86

Run by Darren at 20:21:23.59 on Thu 04/14/2011

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.895.464 [GMT -5:00]

.

AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

.

============== Running Processes ===============

.

C:\PROGRA~1\AVG\AVG10\avgchsvx.exe

C:\PROGRA~1\AVG\AVG10\avgrsx.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\AVG\AVG10\avgtray.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\AVG\AVG10\avgwdsvc.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Darren\Desktop\dds.scr

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

mRun: [nwiz] nwiz.exe /install

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

.

============= SERVICES / DRIVERS ===============

.

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]

R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]

R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 251728]

R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]

R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-30 136176]

.

=============== Created Last 30 ================

.

2011-04-15 00:46:33 -------- d-----w- c:\program files\GridinSoft Trojan Killer

2011-04-14 23:48:07 -------- d-----w- c:\docume~1\darren\applic~1\Uniblue

2011-04-14 23:48:01 -------- d-----w- c:\program files\Uniblue

2011-04-14 23:47:49 -------- d-----w- c:\docume~1\darren\locals~1\applic~1\PackageAware

2011-04-14 16:01:23 -------- d-----w- c:\program files\Help3 Malwarebytes' Anti-Malware

2011-04-14 13:21:13 -------- d--h--w- c:\program files\Help2 Malwarebytes' Anti-Malware

2011-04-14 12:48:54 -------- d--h--w- c:\program files\Help Malwarebytes' Anti-Malware

2011-03-28 17:06:56 -------- d--h--w- c:\docume~1\darren\applic~1\FreeFileOpener

2011-03-28 17:06:02 -------- d--h--w- c:\program files\FreeFileOpener

2011-03-22 20:46:53 81920 ---ha-w- c:\windows\system32\Startup.cpl

2011-03-22 20:39:17 -------- d--h--w- c:\windows\pss

2011-03-22 19:42:47 -------- d--h--w- c:\docume~1\alluse~1\applic~1\pCeAdKnBeOh16639

.

==================== Find3M ====================

.

2011-03-13 12:47:13 3218 ---ha-w- c:\windows\system32\PerfStringBackup.TMP

.

============= FINISH: 20:21:52.60 ===============

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6360

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

4/14/2011 8:29:45 AM

mbam-log-2011-04-14 (08-29-45).txt

Scan type: Quick scan

Objects scanned: 148489

Time elapsed: 6 minute(s), 40 second(s)

Memory Processes Infected: 2

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 1

Registry Data Items Infected: 3

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

c:\documents and settings\all users\application data\abwhpxgioqcwl.exe (Trojan.FakeAlert) -> 1904 -> Unloaded process successfully.

c:\documents and settings\all users\application data\18472756.exe (Trojan.FakeAlert) -> 236 -> Unloaded process successfully.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\aBwHPxGioQCWL (Trojan.FakeAlert) -> Value: aBwHPxGioQCWL -> Quarantined and deleted successfully.

Registry Data Items Infected:

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallPaper (PUM.Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

c:\documents and settings\all users\application data\abwhpxgioqcwl.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

c:\documents and settings\all users\application data\18472756.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

ark.zip

attach.zip

Link to post
Share on other sites

hello

Here is the log from the quick scan, after doing a search I can't find the document and settings folder.

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6367

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

4/15/2011 6:23:22 AM

mbam-log-2011-04-15 (06-23-22).txt

Scan type: Quick scan

Objects scanned: 146821

Time elapsed: 3 minute(s), 16 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Hello again,

I wanted to clarify that I am unable to view or see any folders or files. It is as if they are all hidden or have been deleted. When I click on "My Documents" or even "My Computer" all I see is white space.

I hope this helps.

Link to post
Share on other sites

  • Staff

Hi,

Go ahead and delete that folder.

Please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

-screen317

Link to post
Share on other sites

Hi Screen317, Thank you so much for everything you are doing to help us.

ComboFix 11-04-18.01 - Darren 04/18/2011 19:10:28.1.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.895.678 [GMT -5:00]

Running from: c:\documents and settings\Darren\Desktop\ComboFix.exe

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\explorer(2).exe

c:\windows\system32\linkinfo(2).dll

c:\windows\system32\usp10(3).dll

.

.

((((((((((((((((((((((((( Files Created from 2011-03-19 to 2011-04-19 )))))))))))))))))))))))))))))))

.

.

2011-04-15 00:46 . 2011-04-15 00:55 -------- d-----w- c:\program files\GridinSoft Trojan Killer

2011-04-14 23:48 . 2011-04-14 23:48 -------- d-----w- c:\documents and settings\Darren\Application Data\Uniblue

2011-04-14 23:48 . 2011-04-14 23:48 -------- d-----w- c:\program files\Uniblue

2011-04-14 23:47 . 2011-04-14 23:47 -------- d-----w- c:\documents and settings\Darren\Local Settings\Application Data\PackageAware

2011-04-14 16:58 . 2011-04-14 17:08 -------- d-----w- c:\documents and settings\Administrator

2011-04-14 16:01 . 2011-04-14 16:01 -------- d-----w- c:\program files\Help3 Malwarebytes' Anti-Malware

2011-04-14 13:21 . 2011-04-14 13:21 -------- d-----w- c:\program files\Help2 Malwarebytes' Anti-Malware

2011-04-14 12:48 . 2011-04-14 12:48 -------- d-----w- c:\program files\Help Malwarebytes' Anti-Malware

2011-04-14 04:09 . 2011-04-14 04:09 -------- d-----w- c:\documents and settings\All Users\Application Data\nView_Profiles

2011-03-28 17:06 . 2011-03-28 17:07 -------- d-----w- c:\documents and settings\Darren\Application Data\FreeFileOpener

2011-03-28 17:06 . 2011-03-28 17:06 -------- d-----w- c:\program files\FreeFileOpener

2011-03-22 20:46 . 2002-12-29 06:14 81920 ----a-w- c:\windows\system32\Startup.cpl

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-03-13 12:47 . 2011-03-13 12:47 3218 ----a-w- c:\windows\system32\PerfStringBackup.TMP

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-12-31 39408]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"nwiz"="nwiz.exe" [2006-10-31 1622016]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]

"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-31 86016]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]

2010-09-21 05:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]

2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]

2003-06-07 11:32 50688 ----a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]

2010-05-14 17:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\WINDOWS\\system32\\sessmgr.exe"=

.

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/30/2010 7:27 PM 136176]

.

Contents of the 'Scheduled Tasks' folder

.

2011-04-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-31 00:27]

.

2011-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-12-31 00:27]

.

2011-04-14 c:\windows\Tasks\Malwarebytes' Anti-Malware.job

- c:\progra~1\MALWAR~1\mbam.exe [2010-12-23 00:08]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-04-18 19:14

Windows 5.1.2600 Service Pack 2 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

Completion time: 2011-04-18 19:15:13

ComboFix-quarantined-files.txt 2011-04-19 00:15

.

Pre-Run: 140,871,360,512 bytes free

Post-Run: 140,985,348,096 bytes free

.

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

.

- - End Of File - - 7BED72EA7B68F85241CD045512F2DC75

Link to post
Share on other sites

Hello again,

I tried to run the DDS tool and it worked this time. I am also including the attachment. I had to remove my AVG anti virus to run the Combo Fix, I am wondering if I can download it again or do I need to wait?

Internet Explorer: 8.0.6001.18702

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.895.685 [GMT -5:00]

.

.

============== Running Processes ===============

.

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\Documents and Settings\Darren\Desktop\dds.scr

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll

uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"

mRun: [nwiz] nwiz.exe /install

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab

DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

.

============= SERVICES / DRIVERS ===============

.

S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-12-30 136176]

.

=============== Created Last 30 ================

.

2011-04-19 00:09:36 -------- d-sha-r- C:\cmdcons

2011-04-19 00:07:42 98816 ----a-w- c:\windows\sed.exe

2011-04-19 00:07:42 89088 ----a-w- c:\windows\MBR.exe

2011-04-19 00:07:42 256512 ----a-w- c:\windows\PEV.exe

2011-04-19 00:07:42 161792 ----a-w- c:\windows\SWREG.exe

2011-04-15 00:46:33 -------- d-----w- c:\program files\GridinSoft Trojan Killer

2011-04-14 23:48:07 -------- d-----w- c:\docume~1\darren\applic~1\Uniblue

2011-04-14 23:48:01 -------- d-----w- c:\program files\Uniblue

2011-04-14 23:47:49 -------- d-----w- c:\docume~1\darren\locals~1\applic~1\PackageAware

2011-04-14 16:01:23 -------- d-----w- c:\program files\Help3 Malwarebytes' Anti-Malware

2011-04-14 13:21:13 -------- d-----w- c:\program files\Help2 Malwarebytes' Anti-Malware

2011-04-14 12:48:54 -------- d-----w- c:\program files\Help Malwarebytes' Anti-Malware

2011-03-28 17:06:56 -------- d-----w- c:\docume~1\darren\applic~1\FreeFileOpener

2011-03-28 17:06:02 -------- d-----w- c:\program files\FreeFileOpener

2011-03-22 20:46:53 81920 ----a-w- c:\windows\system32\Startup.cpl

2011-03-22 20:39:17 -------- d-----w- c:\windows\pss

.

==================== Find3M ====================

.

2011-03-13 12:47:13 3218 ----a-w- c:\windows\system32\PerfStringBackup.TMP

.

============= FINISH: 6:56:14.20 ===============

Attach.zip

Link to post
Share on other sites

Hello again,

I was wondering if it was OK now to re-install my anti-virus? I'm certain you are so very busy,

I just wanted to check again and see if you were around.Thank you for all of your help. :)

Link to post
Share on other sites

  • Staff

Hi,

My apologies for the delay.

Yes feel free to install AVG again.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

-screen317

Link to post
Share on other sites

Hi Screen, No worries on the delay. We appreciate everything you are doing to help us.

Here is the ESET log file

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6427

# api_version=3.0.2

# EOSSerial=ea201768b825aa4b84f01de3f33794b6

# end=finished

# remove_checked=true

# archives_checked=true

# unwanted_checked=true

# unsafe_checked=true

# antistealth_checked=true

# utc_time=2011-04-24 04:54:59

# local_time=2011-04-24 11:54:59 (-0600, Central Daylight Time)

# country="United States"

# lang=9

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=1032 16777173 100 76 70092 46722169 0 0

# compatibility_mode=8192 67108863 100 0 0 0 0 0

# scanned=36035

# found=6

# cleaned=6

# scan_time=1681

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054778.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054779.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054780.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054781.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054782.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{3E93D50E-BDE6-4736-AA6C-7A2BD714C85D}\RP154\A0054790.rbf Win32/RegistryBooster application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

**Here is the check-up file:

Results of screen317's Security Check version 0.99.10

Windows XP Service Pack 2

Out of date service pack!!

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

AVG 2011

ESET Online Scanner v3

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

CCleaner

Java 6 Update 23

Out of date Java installed!

Adobe Flash Player

Adobe Reader 9.4.2

Out of date Adobe Reader installed!

````````````````````````````````

Process Check:

objlist.exe by Laurent

AVG avgwdsvc.exe

AVG avgtray.exe

AVG avgrsx.exe

AVG avgnsx.exe

AVG avgemc.exe

``````````End of Log````````````

Thank you again for your help.

DJ84

Link to post
Share on other sites

  • Staff

Hi,

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following programs (if present):

Java

Link to post
Share on other sites

Hello Screen,

I've installed Service Pack 3 and I've followed your other instructions regarding the Java and Adobe updates. Everything is running great

and I think we're all set!

One question for you before we wrap this up - Does the Malwarebytes Pro version stop infections from being installed? I'm looking for a program

that will stop the viruses from even getting past my browser if it's possible. Any recommendations you have for me would be so appreciated.

Many Many thanks for all of your help. :)

DJ84

Link to post
Share on other sites

  • Staff

Hi DJ84,

Glad to hear things are running well! :D

Yes, I highly recommend the PRO version of MBAM. It has the best realtime anti-malware protection that I've ever personally seen, and with it, it's likely that you would have avoided this infection in the first place. ;)

$24.99 gets you a lifetime license of (in my option) the best anti-malware software in the world. With it, you get realtime protection and automatic updates.

If you'd like more information, see our site here:

http://www.malwarebytes.org/products/malwarebytes_pro

Link to post
Share on other sites

"It has the best realtime anti-malware protection that I've ever personally seen, and with it, it's likely that you would have avoided this infection in the first place."

That is exactly what I was hoping you would say. :D

I checked out the link and it doesn't say whether or not the cost of the Pro Version ($24.99) is per computer? We currently have 3 computers that we would need to protect. Do you know if that covers just one PC in the home?

Other then that, thank you again for all of your help, Screen317. You are an asset to this place!

DJ84

Link to post
Share on other sites

  • Staff

Hi DJ84,

Thank you for the kind words. :)

Yes, the license is per computer, so you'll have to purchase a separate license for each computer you have (I think the cost goes down as you buy more, but I haven't looked at that in a while). However, if you ever replace a computer with a new one, you can transfer the license over. Hope I made that clear. ^_^

Link to post
Share on other sites

Yes, crystal clear my friend. Thank you again for all your help and I'll be installing the Pro Version next payday. :D

Many thanks,

DJ84

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.